Monday, 8:47 a.m.
Three emails are waiting. One of them is a trap.
Coffee in hand, you open your inbox: a storage warning from IT, a note from the CEO, an all-staff maintenance notice. In the next ten minutes you'll learn to tell — at a glance — which one wants to hurt you.
Why This Email Matters
A phishing email isn't after your computer — it's after your credentials and your trust. And it only needs to work once.
What One Click Sets in Motion
This is the documented pattern of a real breach — walk through it.
- 08:49
The click
One employee opens the “quota” link. The page looks exactly like the company login.
- 08:50
Credentials harvested
The fake page silently forwards the typed password to the attacker — and redirects to the real site, so nothing feels wrong.
- 11:20
The account becomes the weapon
The attacker now mails the whole team from a real internal address. Every red flag you know disappears — except context.
- Day 3
Ransomware
Files encrypted across shared drives. Recovery is measured in weeks and six figures — all from one Monday-morning click.
Find the Red Flags
This is the first email from your inbox — the “storage warning”. It carries four red flags. Find each one by clicking directly on the email.
Flag 1 of 4: The display name says “Acme IT Support” — but something right next to it gives the game away. Click it.
Flag 2 of 4: Attackers need you to act before you think. Click the sentence built to do exactly that.
Flag 3 of 4: The button says “Verify Mailbox” — but where does it REALLY go? Click the true destination.
Flag 4 of 4: One more classic payload carrier is sitting in this email. Click it.
Same Layout, Different Intent
Email three is a maintenance notice from IT — and here's the uncomfortable truth: a clone of it would use the same logo, same layout, same signature. Drag the slider and find what CAN'T be faked.
The One Signal That Can't Be Faked
In both the storage warning and the IT clone, the logo, layout and tone were perfect. What was the reliable tell in BOTH cases?
The Four Flags, In Depth
You've now FOUND all four in the wild. Here's the pattern behind each, with the variant you'll meet next time.
Lookalike domains
acme-mail-services.net, acmе.com (that ‘е’ is Cyrillic) — read the part just before the last dot, every time. Display names are free text; domains are the identity.
Manufactured urgency
“24 hours”, “final notice”, “account suspended”. Real systems give you weeks and don't threaten. Pressure exists for one reason: to switch off the part of you doing this course.
Mismatched links
The text says portal.acme.com; the hover says acme-mail-quota-fix.com. On mobile, long-press to preview. When in doubt: don't travel through the link — go to the site yourself.
Unexpected attachments
Invoices you didn't expect, “voicemails” as .zip, reports nobody mentioned. The question is never “is this file safe” — it's “was this file expected”.
You've Spotted It. Now Don't Touch It.
Detection without the right response still ends in a breach story. The protocol is three verbs:
STOP — no clicks, no replies, no forwarding (forwarding delivers the bait to a colleague).
REPORT — the report button isn't bureaucracy; it triggers removal of the same email from everyone else's inbox.
VERIFY — if it names a person or a vendor, contact them through a channel you already had. The phone number inside the email belongs to the attacker.
Already clicked? Report anyway, immediately. Security teams reward fast honesty — the timeline you saw earlier is what silence buys.
Order the Response
The storage-warning email is still open on your screen. Put your next moves in order.
- Stop — hands off links, attachments and the reply button
- Re-check the sender domain and the link's true target
- Hit report — it protects every colleague who got the same email
- Verify with IT through the intranet or a known number
8:52 a.m. — Clear Your Inbox
Back to your Monday inbox. The storage scam is reported. Two emails remain — and a new one just arrived. Three decisions, three lives.
Email 2 — “from the CEO”: [email protected], subject Urgent - confidential: “Are you at your desk? I need gift cards for a client surprise. Keep this between us.”
- Correct. Executives don't route purchases through gift cards, don't demand secrecy, and don't mail from Gmail. This one script costs companies billions a year — you just declined your share.
- The three levers just worked on you: authority (CEO), urgency (now), secrecy (tell no one — i.e., let no one sanity-check this). A real executive request survives daylight.
Email 3 — the maintenance notice: from [email protected], the Saturday-maintenance announcement you compared earlier. Right domain, no login request, expected context.
- Correct — and this matters as much as catching the scams. Reporting everything buries the security team and dulls your own signal. Judgment, not paranoia.
- Understandable instinct, wrong call — this one has the real domain, expected context, and no request. The skill you're building is telling the difference, not fearing everything.
08:58 — new arrival: “DocuShare: Q3_Bonus_Structure.pdf shared with you” — from [email protected], requesting your company login to view the file.
- Correct — the bait is tuned (who wouldn't peek at bonus structures?), but the mechanic is naked: your company password has no business on a non-company domain. Ever.
- Curiosity is the payload here. One rule survives every disguise: company credentials go only into company domains.
docushare-files.comisn't one.
Name What You Report
Precise names speed up the security team. Match each attack to its term.
The Rule That Survives Every Disguise
If an email names a person or a vendor, verify through a ___ channel — never through contact details the email itself provides.
Your Morning, Scored
Here's how your Monday went:
Re-run “Find the Red Flags” — sender domain and link targets are the two zones people miss under time pressure.
Replay the inbox — the CEO-fraud triangle and the credentials-on-foreign-domain rule are the expensive ones.
Review the four terms and the second-channel rule.
9:00 a.m. — Inbox Zero, Breach Zero
Thirteen minutes ago, three emails were waiting and one was a trap. You found four red flags on a live phish, told a clone from the real thing, and cleared an inbox without leaking a single credential.
Before you close this tab: find the report-phishing button in your real mail client — so on the Monday this actually happens, your hand already knows the way.